Exploring Telecom Use Cases to Enhance Security and Protect Your Customers from Fraud

Explore real-world telecom fraud detection use cases that help operators identify suspicious activity, strengthen security, and protect subscribers.

Table of content

Listen to this article

Telecom Fraud Detection Use Cases for Enhanced Security
10:20

This is the second article in our series, where Polystar's Professional Services team shares practical use cases and insights relevant to telecom operations.

The flexibility and comprehensive data available means that Kalix Analytics can easily be adapted to new use cases that target fraudulent activities. By identifying the clues you need, you can create new views and workflows that help you track down and pinpoint suspicious activities.

Fraud Is a Constant. Can You Leverage Your Own Innovations to Stay Ahead?

Fraud continues to bedevil mobile networks, threatening your customers and their friends and families. Fraudsters are, unfortunately, more than capable of innovation, creating new ways to target victims and developing sophisticated tools to do so.

As such, fraud is a moving target – and operators must stay ahead of bad actors. This requires innovation – and it’s an area in which our partners have forged ahead with custom initiatives, working in collaboration with our Professional Services team.

In this next instalment of our series on new use cases, we’ll highlight some of these innovations and show how they help protect against common and emerging fraud attempts.

A middle-aged man reading a suspicious SMS

Tackling SMS Fraud

According to UK regulator, Ofcom, 40% of mobile subscribers in the UK reported receiving at least one suspicious message on their mobile phone during a three-month period of 2026. At the same time, Ofcom also states that mobile operators are blocking at least 600 million messages each year.

Globally, the threat is significant. Juniper Research reckons that the cost of SMS fraud in terms of subscriber losses will be around $71 billion in 2026. However, this sum represents a decline from $80 billion in 2025.

So, clearly, defenses are in place and can offer sophisticated protection – but gaps remain that enable fraudulent messages to leak through, and scammers are engaged in a continual arms race to try to break through the defensive barriers erected by operators.

And that’s why your peers are taking steps to leverage capabilities integral to Kalix Analytics to build new methods of detection that supplement other measures, like firewalls and deep packet inspection tools.

A New Screening Capability

For example, one operator, in conjunction with our Professional Services team, implemented a new screening capability to try to zoom in on SMS traffic and to seek to identify potential fraudsters.

In this case, the operator wanted to try to identify sources of potential fraud that were using its network to initiate activities that targeted users outside its network. Combatting fraud is a shared activity and operators have responsibilities to protect their peers and users outside their network from threats that might originate in their own.

So, what we were looking for is a list of those numbers that send the highest volumes of SMS. With a list generated through a Kalix Analytics portal view, individual numbers in the list can be checked to see if the destination of the traffic sent is another network – either in the same country or elsewhere.

This allows senders of potentially suspicious traffic to be identified and then verified. Traffic can be legitimate, but you need to validate this from the observed activities – and sending high volumes of messaging traffic from a personal phone number might well be a red flag.

In the battle against fraud and spam, we have to take a broad view. There may well be obvious signals that can be caught in firewalls or other defenses. But, indicators like high volume sending from a single number could also be negative signs.

The ability to quickly tune Kalix Analytics so that such target lists can be generated was an easy win for the operator and added another metric that could be tracked and used by the security team. Constant vigilance requires, not just proven tools, but also the ability to capture ideas from your teams so they can be realized as additional levels of scrutiny.

Senior telecom engineers working together to detect suspicious activities

Using Mobility as an Indication of Suspicious Activities

Mobility is, of course, central to your mobile networks. But, unless your customers are on a high-speed train, or driving, they don’t tend to move around all that quickly – and, even in those cases, likely routes are predictable and may also match established patterns.

Nothing to see here. Unless, that is, devices with the same IMEIs can be seen attaching to the network in different locations with gaps of only a short time interval. Absent teleportation, or even an obvious path from one location to another, this could suggest that you have a problem.

The problem here is that devices and their identities might be being used by more than one user during given time periods. In other words, we could just have some cloned devices present in the network.

Spotting Devices Used by Several People

But how can we take this theory and turn it into a workable use case that can be applied to automatically detect such activities? One operator worked with Professional Services to realize such a solution, having been stung by such activities – and having obligations to defend against such threats.

This required a new workflow to accelerate the process. Spotting devices that are being used by several people is straightforward – we can see the IMEI and IMSI, so can easily correlate this data. IMEIs that have multiple IMSIs can then be revealed.

But what are they actually doing? By selecting “user details”, the team would then be taken to another view in which traffic for these users is analyzed – and traffic activities could be checked.

We noted that location is a key variable here, so the workflow also includes network attachments and locations, allowing Kalix Analytics users to spot any suspicious locations that do not represent normal behavior. If the recorded IMEIs are far apart, they probably haven’t got there legitimately.

So, what we’re doing here is taking readily available information but creating a process that allows such indicators to be captured in a single workflow and inspected, so that further investigations can be triggered.

What it shows is that the existing capabilities of Kalix can be leveraged to deliver views that aid the fight against fraud – because different data can be aggregated, correlated and filtered to expose activities that could represent threats.

And, you can work with our team to create novel ways to combine data of interest and build workflows that support your other security measures. The information revealed supports your overall initiatives and adds more evidence to your case.

A business woman receiving a suspicious call on her mobile phone

Mass Calling

When many calls from a single number are made in a short period of time, it can be indicative of a Distributed Denial of Service attack, or a different kind of threat, such as fraudulent calls to entice users into sharing privileged information.

In either case, it’s essential to be able to understand who has made the calls, to whom, and over what time period. So, together with an operator, the Professional Services team created new “Mass Call” lists, which displays the A-numbers that have made the most calls, as well as the B-numbers that have been dialed.

In addition, the list also shows the number of call attempts for a specified time interval. From this, you can easily see which numbers are making the highest number of outbound calls and the frequency with which they attempt to do so. Users can access this information by clicking on either the calling or called number from the lists exposed.

As a result, further analysis can be conducted, using the events table and applying different filters from those available. Again, this doesn’t prove fraud or malicious activities, it simply provides clues that can be used as evidence to guide further actions and remedial measures. And, it also gives further auditable records that can be used as part of investigative activities.

Finding Clues and Building Evidence

The important thing here is the word “clue”. None of the measures described above offers definitive proof of fraudulent or malicious activities. But they all provide clues and contribute to guiding searches and further actions.

All of the relevant data is already available in Kalix Analytics, but it needs to be accessed in the right way, which may be different from a standard view in the portals. This means that the teams in question have thought about data they would like to explore and what they want to see correlated, as well as workflows to make further queries.

The fight against fraud will never be over. But then the imagination of your teams will never be exhausted either. The flexibility of Kalix Analytics and the comprehensive data that it can process can combine with the creative skills of your team and our Professional Services staff to generate new views and workflows that allow you to home in on the kinds of clues that are already in your network.

Capturing those clues helps you to bolster threat detection and catch incidents as they happen and before the impact more customers, both in your network and in those of your peers.

So, if you have ideas for data discovery and exploration that you don’t think you can execute on your own, get in touch and we’ll help you turn those into simple tools that can supplement your other activities. 


 

About the Author

Jonas Nahlin is Director of Professional Services at Polystar. Together with his team of highly skilled telecom engineers, data analysts, and solution architects, he works closely with customers to transform data into actionable insights that improve service assurance, customer experience, and operational efficiency.

Read the first article in the series: Innovating in Service Assurance and Customer Experience Management through New Use Case Scenarios

In the next article, we'll explore innovative use cases to enhance network service assurance with micro innovations. 

Would you like to know how Polystar can support fraud detection in telecom operations?